Description
Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.4.4-rc.3, the scheduler's default unauthenticated v1 gRPC flow accepts attacker-controlled PeerHost.Ip and PeerHost.DownPort values through RegisterPeerTask and ReportPeerResult, storeHost copies those values into resource.Host, and handlePeerSuccess invokes Peer.DownloadTinyFile() for a TINY task. DownloadTinyFile() in scheduler/resource/standard/peer.go builds an HTTP GET request from the supplied address without destination validation, allowing a remote attacker to probe loopback, link-local, and private services and place up to TinyFileSize, 128 bytes, of a response in Task.DirectPiece for later retrieval. PeerHost.DownPort is restricted to ports 1024 through 65534, and the issue provides read SSRF rather than remote code execution. The remediation blocks loopback and link-local targets, while RFC1918 destinations remain reachable because IsGlobalUnicast accepts private ranges. This issue is fixed in 2.4.4-rc.3.
Published: 2026-09-15
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure via SSRF
Action: Patch Now
AI Analysis

Impact

Dragonfly is an open source peer‑to‑peer file distribution system that, before the release of version 2.4.4‑rc.3, allows unauthenticated users to specify a PeerHost.Ip and PeerHost.DownPort via the v1 gRPC RegisterPeerTask or ReportPeerResult methods. The scheduler stores these values into resource.Host and later calls Peer.DownloadTinyFile() for a small TINY task. In that function the code constructs an HTTP GET request directly from the supplied address, performing no validation of the destination. This enables an attacker to cause the scheduler to send outbound HTTP requests to loopback, link‑local, or RFC1918 addresses, placing up to 128 bytes of the response payload into Task.DirectPiece for later retrieval. The vulnerability therefore provides read‑type SSRF (CWE‑918) rather than remote code execution. Attempts to target private ranges are not blocked because IsGlobalUnicast accepts RFC1918 addresses, though loopback and link‑local targets are prevented by remediation in the fixed release.

Affected Systems

Dragonfly OSS Scheduler, any version prior to 2.4.4‑rc.3. The vulnerability exists in the default scheduler configuration that accepts unauthenticated gRPC requests.

Risk and Exploitability

The CVSS score is 5.5, indicating a medium severity. The EPSS score of 0.00487 reflects a very low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires the attacker to send a malicious RegisterPeerTask or ReportPeerResult request to an exposed scheduler endpoint, which then performs an outbound HTTP GET. Because the affected port range is 1024–65534, many internal services could be probed, but the payload size is limited to 128 bytes, restricting the amount of data returned.

Generated by OpenCVE AI on September 17, 2026 at 16:15 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Dragonfly to version 2.4.4‑rc.3 or later where the issue is fixed.
  • Restrict access to the scheduler’s gRPC v1 endpoint to trusted clients only, and enforce authentication or network segmentation to prevent unauthenticated requests.
  • Configure firewall or network controls to block outbound requests from the scheduler to loopback, link‑local, and private IP ranges, mitigating potential SSRF exploitation.

Generated by OpenCVE AI on September 17, 2026 at 16:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-chwm-m7g7-685g Dragonfly scheduler v1 and v2 gRPC unauthenticated SSRF via attacker-controlled PeerHost in DownloadTinyFile
History

Wed, 16 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Dragonflyoss
Dragonflyoss dragonfly2
Vendors & Products Dragonflyoss
Dragonflyoss dragonfly2

Tue, 15 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Description Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.4.4-rc.3, the scheduler's default unauthenticated v1 gRPC flow accepts attacker-controlled PeerHost.Ip and PeerHost.DownPort values through RegisterPeerTask and ReportPeerResult, storeHost copies those values into resource.Host, and handlePeerSuccess invokes Peer.DownloadTinyFile() for a TINY task. DownloadTinyFile() in scheduler/resource/standard/peer.go builds an HTTP GET request from the supplied address without destination validation, allowing a remote attacker to probe loopback, link-local, and private services and place up to TinyFileSize, 128 bytes, of a response in Task.DirectPiece for later retrieval. PeerHost.DownPort is restricted to ports 1024 through 65534, and the issue provides read SSRF rather than remote code execution. The remediation blocks loopback and link-local targets, while RFC1918 destinations remain reachable because IsGlobalUnicast accepts private ranges. This issue is fixed in 2.4.4-rc.3.
Title Dragonfly scheduler v1 gRPC unauthenticated SSRF via attacker-controlled PeerHost in DownloadTinyFile
Weaknesses CWE-918
References
Metrics cvssV4_0

{'score': 5.5, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Dragonflyoss Dragonfly2
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-16T18:11:53.807Z

Reserved: 2026-06-15T20:07:02.186Z

Link: CVE-2026-54637

cve-icon Vulnrichment

Updated: 2026-09-16T18:11:28.359Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T15:17:18.443

Modified: 2026-09-30T17:51:56.193

Link: CVE-2026-54637

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T19:30:06Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)